CVE-2024-11138: DedeCMS friendlink_add.php unrestricted upload
Published Nov 12, 2024
·Updated
A vulnerability classified as problematic has been found in DedeCMS 5.7.116. This affects an unknown part of the file /dede/uploads/dede/friendlinkadd.php. The manipulation of the argument logoimg leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
DedeCMS Dedecms=5.7.116
Event History
Nov 12, 2024
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11138?
CVE-2024-11138 is classified as a problematic vulnerability.
2
How do I fix CVE-2024-11138?
To mitigate CVE-2024-11138, ensure that file upload permissions are restricted and validate all uploaded files.
3
What software is affected by CVE-2024-11138?
CVE-2024-11138 affects DedeCMS version 5.7.116.
4
Can CVE-2024-11138 be exploited remotely?
Yes, CVE-2024-11138 can be exploited remotely due to unrestricted upload capabilities.
5
What part of DedeCMS is impacted by CVE-2024-11138?
CVE-2024-11138 impacts the file located at /dede/uploads/dede/friendlink_add.php.